As a standard practice, we regularly update certificates for all Aiven for Kafka services, regardless of whether they utilize certificates or not.
If your service has TLS encryption enabled along with SASL, notifications for certificate expirations will persist. By default, this feature is enabled for every Kafka service.
To cease receiving these notifications prior to certificate expiration,
- it’s necessary to disable the
kafka_authentication_methods.certificate
setting within the advanced configuration of the respective Kafka service.